started · updated
Firmware-level malware and perimeter exploits rise in Q3 2026
Cybersecurity trends in the third quarter of 2026 show a significant rise in sophisticated attacks targeting network infrastructure and supply chains. Threat actors are increasingly utilizing firmware-level malware to establish persistence. These implants reside beneath the operating system layer, allowing them to survive reboots, operating system reinstalls, and factory resets.
Specific incidents include the discovery of the ‘Firestarter’ backdoor on Cisco firewalls by a U.S. federal agency, and the identification of a new Cyclops Blink variant on Cisco Firewall Management Center devices by Sophos researchers. In these cases, traditional remediation is often ineffective, sometimes requiring physical hardware reflashing.
Additionally, there has been a surge in attacks on perimeter devices such as NetScaler and Cisco FMC, where attackers exploit vulnerabilities to install web shells for remote command execution. The number of new listings in CISA’s Known Exploited Vulnerabilities (KEV) catalog doubled compared to the same period in 2025, with a high percentage involving web, server, and network perimeter devices. Supply chain attacks also remain a threat, with malicious packages distributed through official registries like npm and PyPI.